Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41470

Опубликовано: 19 мая 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.

EPSS

Процентиль: 40%
0.00486
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.

CVSS3: 5.9
debian
3 месяца назад

LIVE555 before 2026.04.22 contains an authorization bypass vulnerabili ...

CVSS3: 5.9
github
3 месяца назад

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.

EPSS

Процентиль: 40%
0.00486
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-863